Privacy Policy

Last updated: July 22, 2026

1. About This Policy

PineHook Systems Inc. (“PineHook,” “we,” or “our”) takes the protection of your privacy very seriously. That is why this privacy policy (the “Policy”) provides you with information about how we collect, use, and disclose (collectively, “process,” “processed,” “processing”) your personal information when you use our signal relay service and plugin between TradingView and MetaTrader 5 (the “Service”), our website at www.pinehook.io (the “Website”), and any interaction with an employee, representative, or authorized subcontractor of PineHook, including via email, phone, in person, or via videoconference. However, this Policy does not apply to third-party content and platforms accessible through our Service, including via third-party links or features. These third parties may process your personal information in accordance with their respective privacy policies. We are not responsible for such processing, and we encourage you to carefully review the policies of these third parties.

In addition to the other applicable provisions of this Policy, if you reside in California, Europe or the United Kingdom, you may have additional rights under applicable laws. You will find additional information regarding these rights in the respective appendices titled “United States,” “Europe,” and “United Kingdom”.

By accessing our Website or using the Service, you acknowledge that you have read this Policy and freely, knowingly, and specifically consent to the collection, use, and disclosure of your personal information as described below. You may withdraw your consent at any time by changing your preferences in the Settings page or by contacting us at the address provided in the “Contact Us” section.

2. Personal Information

For the purposes of this policy, “Personal Information” refers to any information relating to a natural person that allows, directly or indirectly, the identification of that person. However, laws applicable in certain jurisdictions, including Canada and Quebec, may not consider professional contact information to be personal information. In these jurisdictions, Personal Information therefore does not include professional contact information, such as your name, title, or business contact details, when used in a strictly professional context. Personal Information also excludes information that has been anonymized or aggregated in a manner that is irreversible and in accordance with the criteria established by applicable laws and regulations.

When you use the Service and/or the Website, we may collect the following Personal Information:

  • Your contact information, such as your last name, first name, email address, mailing address, and phone number, to identify you and communicate with you;
  • Your login and account information, such as the date you registered, your username, password (stored as hashes; we never store your plaintext password), IP address, country of residency, browser user agent, device fingerprint, session identifier, referrer URL, and locale, security metadata and information regarding your browser or the device used;
  • Technical information regarding your use of our services, such as session duration, your interactions with our services, and server logs including request timestamps and HTTP status codes;
  • Data related to cookies and identifiers, as described in the “Cookies and Similar Tools” section;
  • Account balance/equity snapshots;
  • Payment data, including your subscription plan selection (credit card numbers and billing details are processed exclusively by Stripe; we never receive or store card numbers);
  • And any other Personal Information that you have provided to us or for which you have consented to its disclosure.

3. How Do We Collect Your Personal Information?

Directly from you

Generally, we obtain the Personal Information we need directly from you, for example when you fill out registration forms on the Website or the Service, when you contact us, or when you use the Service or the Website.

On a legal basis such as your consent

The legal basis for processing your Personal Information is generally consent, unless applicable law provides for another permissible legal basis (for example, to comply with our legal obligations, when necessary to establish, exercise, or defend a legal claim or legal proceeding, or for contractual necessity to provide the Service).

When the processing involves sensitive Personal Information, such as financial account identifiers, such information is collected and processed only with the consent of the individuals concerned or where necessary for the performance of the Service. You may withdraw your consent to the processing of your sensitive Personal Information at any time, in accordance with the terms set forth in this Policy.

Your consent to the processing of your Personal Information will be renewed in each of the following circumstances: (i) when PineHook makes a significant change to this Policy or the Service’s Terms of Use. In such a case, PineHook will inform you of the nature of the changes made and will request your renewed consent before continuing to process your Personal Information; (ii) when required by applicable law.

If you do not renew your consent within the timeframes set forth above, PineHook will cease processing your Personal Information for the purposes requiring your consent, subject to its legal retention obligations and any other applicable legal basis permitting the continuation of processing.

By a business partner, with your consent

Subject to your consent with third-party partners, such as Stripe for payment processing, we may collect your Personal Information directly from these third-party partners, who may submit any information you have provided to them and that they make available to us, with your consent.

Refusal of Collection and Withdrawal of Consent

You have the right, if you wish, to refuse the processing of your Personal Information. You may also, at any time, and subject to reasonable notice and any applicable legal or contractual restrictions, withdraw your consent (if applicable) to the processing of your Personal Information in our possession by contacting us. You should be aware, however, that if you choose not to provide your Personal Information, this may prevent you, for example, from using the Service, as this information is essential for accessing it. You may contact us as indicated in the “Contact Us” section to submit any requests in this regard.

4. Why Do We Collect and Use Your Personal Information?

We collect only the Personal Information necessary to achieve the following objectives:

  • To provide access to the Service, its features, and its products;
  • To process transactions and manage billing;
  • To provide support to users of the Service or the Website;
  • Respond to your questions, requests, comments, or complaints;
  • Develop new features and products for users;
  • Personalize your experience on the Service;
  • Prevent and detect fraud, abuse, or suspicious activity;
  • Conduct statistical analyses and market research;
  • To personalize the content available to you on the Service;
  • To protect our legal rights and comply with our legal and regulatory obligations;
  • Any other use for which you have given your consent, including communications via newsletters.

We do not use automated decision-making processes, including profiling, for decisions that produce legal effects concerning you. However, certain features of PineHook rely on automated systems for rate limiting (throttling of API requests based on your subscription tier), signal authentication (validation of license keys), and fraud detection (detecting trial abuse and referral fraud). You will be notified of any automated decisions that significantly affect you, and you may contact our Privacy Officer to request human review of an automated decision.

5. With Whom Do We Share Your Personal Information?

PineHook does not rent or sell any of your Personal Information to third parties and will not share it with third parties without your consent, unless required by law or for the purposes set out above. PineHook will only share your Personal Information as follows:

With our employees. As part of their work, our employees may need to access your Personal Information, for example when you contact us for assistance. Their access is limited to what is necessary for the performance of their duties.

With our strategic partners. PineHook may share your Personal Information with its partners, service providers, and vendors, including but not limited to Stripe (payment processing), DigitalOcean (cloud hosting), Cloudflare (DNS, CDN, and DDoS protection), Brevo (transactional email delivery), and third-party AI Service Providers that have committed to a zero-retention policy for personal information (AI-powered chat assistant) to the extent that such disclosure is necessary for the purposes listed above. When PineHook shares your Personal Information with third parties, it implements reasonable contractual and technical safeguards to ensure that these third parties maintain the confidentiality of all Personal Information they process (to the extent required by applicable laws).

All providers listed above operate under written data processing agreements. The data shared with them is limited to what is necessary for the service they provide.

Please note that these third parties may be located in countries other than your own, in which case PineHook takes appropriate measures, as outlined below in the section “Where do we transfer your Personal Information?”

With third parties you have designated. The Service may include features that allow you to share your data with third parties or via external services. You acknowledge that PineHook has no control over the choice of recipients or the use made of your data once shared, and cannot be held responsible for the confidentiality, security, or use of such information outside the Service. Any sharing via external services is subject to the terms and conditions of those third-party services, and you are responsible for complying with them.

When required by law. PineHook may share your Personal Information if required by law or if it believes in good faith that such action is necessary to: (a) comply with the law; (b) comply with an order from a competent judicial authority in any jurisdiction; (c) comply with a legal proceeding served on PineHook; (d) protect and defend the rights or property of PineHook; (e) enforce or verify your compliance with any part of the agreements you have entered into with PineHook, if applicable; (f) prevent fraud or any other illegal activity perpetrated via the Service; or (g) act in urgent circumstances to protect the personal safety of Service users or the general public.

Business Transfers. We may share your Personal Information without your consent when our business operations require it (for example, in the event of a merger, acquisition, bankruptcy, or sale of assets). In such situations, we may also share all or part of your Personal Information with the relevant third party (or its advisors) as part of a due diligence process.

6. Third-Party Authentication Services

We may offer you the option to create an account or log in to the Service using your credentials from third-party service providers, such as Google, Apple, or any other provider we may integrate at our discretion (collectively, the “Third-Party Authentication Services”). By choosing to authenticate through a Third-Party Authentication Service, you acknowledge and agree that: (i) your use of these services remains governed by the terms of use and privacy policies of these third-party providers, which are independent of this Policy; and (ii) PineHook has no control over the Third-Party Authentication Services and disclaims all liability for their availability, operation, security, or any harm arising from their use, malfunction, or unavailability.

TradingView and MetaTrader 5 Plugin Integration

The Service operates as a signal relay between TradingView and MetaTrader 5 via a locally installed plugin. This section describes how we handle your data in connection with this integration.

The Service receives trading signals from TradingView via webhook alerts that you configure in your TradingView account. PineHook does not access your TradingView account credentials and does not log into TradingView on your behalf. The webhook URL provided by PineHook contains a unique license key that authenticates signals sent to the Service. You are responsible for keeping this license key confidential. If you believe your license key has been compromised, you may regenerate it through your PineHook dashboard.

To execute trades on your behalf, the Service uses a locally installed plugin on your device that communicates with your MetaTrader 5 platform. PineHook does not require, collect, or store your MetaTrader 5 account credentials. The plugin operates on your local device and interfaces directly with your MetaTrader 5 installation. You are responsible for maintaining the security of your local device and MetaTrader 5 account.

When the Service processes a trading signal, it may collect and retain the following information: (i) the signal payload received from TradingView (including symbol, action, and any parameters you have configured); (ii) trade execution details returned by MetaTrader 5 (including order identifiers, execution prices, and timestamps); (iii) account balance and equity snapshots at the time of trade execution; and (iv) error logs if a trade fails to execute. This information is retained in accordance with the “Retention and Destruction” section of this Policy.

7. Artificial Intelligence (AI) Features

The Service includes access to an AI-powered chat assistant available through the dashboard (the “AI Chatbot”). The AI Chatbot is designed to assist you with simple requests and inquiries related to your use of the Service. The AI Chatbot has access only to your User Content and Account data; it does not have access to the data of other users.

To make AI features available through the Service, we use third-party artificial intelligence service providers (collectively, “AI Service Providers”). These AI Service Providers only have access to the Personal Information you submit via the AI features of the Service or the Personal Information available on your Account and are limited to the Personal Information strictly necessary for the intended purposes. PineHook has contractual arrangements with its AI Service Providers that require them to maintain zero data retention policies with respect to your User Content and interactions with the AI Chatbot.

Notwithstanding the foregoing, you acknowledge that the use of AI Service Providers involves inherent risks, and PineHook does not guarantee that AI Service Providers will comply with their contractual obligations at all times. You agree not to submit any sensitive personal information, financial account credentials, or other confidential information to the AI Chatbot that you would not want processed by third-party AI Service Providers.

We regularly assess the privacy and security practices of our AI Service Providers. When we share your Personal Information with AI Service Providers, we implement reasonable contractual and technical safeguards, including data processing agreements, to ensure that these providers maintain the confidentiality of all Personal Information they process (to the extent required by applicable laws). AI Service Providers do not use your Personal Information to train, improve, or develop their artificial intelligence models unless a separate and explicit consent has been obtained from you for that purpose.

If you are not satisfied with the AI Chatbot’s response or if your request requires human assistance, you may escalate your inquiry to a human representative at any time by following the escalation instructions provided within the AI Chatbot interface or by contacting us directly at [email protected].

8. Where Do We Transfer Your Personal Information?

The Personal Information we collect is stored in secure systems hosted on DigitalOcean servers located in the United States, with backups in Canada. We may also engage the services of agents and service providers who may be located outside of Canada, including AI Service Providers for the AI Chatbot. However, we strive to protect the Personal Information under our control, including Personal Information entrusted to an agent or service provider, whether they are located in Canada or in other jurisdictions or countries. In particular, we strive to limit their access to Personal Information to what is necessary to perform their assigned duties. Our US-based providers participate in the EU-US Data Privacy Framework or maintain Standard Contractual Clauses (SCCs) as applicable. Before any cross-border transfer, we assess that the receiving jurisdiction provides adequate privacy protection. If you have any further questions on this matter, you may contact us as indicated in the “Contact Us” section.

9. How Do We Protect Your Personal Information?

With Necessary and Appropriate Security Measures

We strive to implement necessary and appropriate security measures and policies, based on the sensitivity of the information, to ensure the confidentiality of Personal Information in our possession or under our control, including, without limitation, conducting privacy impact assessments for the processing of sensitive Personal Information. In doing so, we follow generally accepted industry standards. Personal Information under our control is therefore accessible only to individuals who are authorized to access it, who are bound by confidentiality agreements, and who access it only when necessary to perform their duties. Appropriate physical, technical, and administrative security and protection measures have been implemented and are maintained to minimize the risk of incidents. These measures include, for example, restricted access to premises and Personal Information; encryption of data in transit and at rest; access and permission management; activity logging; security incident response protocols; and notification in the event of a privacy incident, in accordance with applicable laws. The Service’s security mechanisms are subject to regular audits, including penetration tests.

PineHook is committed to promptly addressing any identified vulnerabilities. It should be noted, however, that no method of transmission over the Internet or electronic storage is completely secure or error-free. Although we implement rigorous security measures to protect your Personal Information, no data transmission or storage system is entirely infallible. We are, however, committed to doing everything reasonably possible to ensure the protection of your information. You acknowledge that the security of online transactions and the security of communications sent electronically or by mail cannot be guaranteed. You provide information to us via the Internet or by mail at your own risk. We encourage you to exercise caution when using the Internet.

Payment Information

The financial information you provide at the time of payment is processed by Stripe. Credit card numbers and billing details are processed exclusively by Stripe; we never receive or store card numbers. This information is processed in accordance with security and encryption standards in force in the payments industry (e.g., the PCI DSS standard).

Children’s Privacy

PineHook is not intended for anyone under the age of 18. We do not knowingly collect personal information from minors. Because our Service involves financial trading, we do not permit accounts for anyone under 18. If we discover that a minor has created an account, we will delete it promptly.

If you believe that Personal Information has been collected from minors without the necessary consents, you may contact PineHook as indicated in the “Contact Us” section.

Respecting Your Device’s Privacy Preferences

PineHook automatically respects the privacy settings you have configured on your device, such as the “Do Not Track” feature and Global Privacy Control. When either signal is present, we treat it as a refusal: analytics and advertising cookies are not loaded and no cross-site tracking takes place, regardless of any preference previously stored on your device.

Security Incident Management

In the event of actual or suspected unauthorized access to confidential information or PineHook’s systems, PineHook will implement a formal process to contain, analyze, correct, and document the incident, in compliance with applicable laws. When PineHook determines that unauthorized access has occurred, it undertakes to promptly notify you if you are affected by the unauthorized access or are likely to suffer harm as a result. Upon discovery of any unauthorized access, PineHook commits to immediately taking steps to: (i) terminate the unauthorized access; (ii) manage and mitigate the impact of the unauthorized access; and (iii) develop a strategy to prevent unauthorized access in similar circumstances.

10. Retention and Destruction

Your Personal Information will be retained only for as long as necessary to fulfill the purposes for which it was collected, or in accordance with PineHook’s legitimate interests, or to comply with applicable legal, tax, or regulatory requirements. At the end of this period, we will endeavor to destroy or anonymize this information.

To determine the appropriate retention period for your Personal Information, we take into account the amount, nature, and sensitivity of the Personal Information in question, the potential risk of harm resulting from unauthorized use or disclosure of your Personal Information, the purposes for which we process your Personal Information and the possibility of achieving those purposes by other means, as well as any applicable legal, tax, or regulatory requirements.

11. What Are Your Rights?

Depending on applicable law, you may have certain rights regarding your Personal Information, such as the right to data portability, the right to access or correct your Personal Information, and the right to withdraw your consent (where applicable). To exercise any of these rights (to the extent they are available), please contact us at the address listed in the “Contact Us” section.

In addition, you may file a complaint with PineHook’s Privacy Officer if you are dissatisfied with how we process your Personal Information or with our compliance with this policy. The law also allows you to file a complaint with a privacy commissioner or any other competent supervisory authority responsible for the protection of Personal Information.

12. Cookies and Other Similar Tools

A cookie is a small text file that is stored in a dedicated location on your computer, mobile device, tablet, or other device when you use your browser to visit an online service. Other tracking technologies, such as web beacons and tracking pixels, may be used for similar purposes. In this policy, all such tracking technologies are collectively referred to as “cookies.” All Personal Information collected through the use of cookies by or on behalf of PineHook is treated with the same level of confidentiality as any other Personal Information held by PineHook.

  • Essential cookies. PineHook collects essential cookies. These cookies and similar technologies are necessary for the Services to function and cannot be disabled in our systems. Strictly necessary cookies must be present for the Services to provide basic functions and do not require express consent; these may include login, authentication, maintaining your authenticated sessions, secure management of your access, as well as the proper functioning of real-time connections to the database and the AI-powered chatbot.
  • Advertising Cookies. Subject to your prior consent, we may use advertising cookies, including those from Google and other third-party advertising networks, in order to present you with personalized and relevant advertisements, measure the effectiveness of our advertising campaigns, and create lookalike audiences. These cookies track your browsing activity on our Services, our Website, and other sites in order to serve you advertisements tailored to your interests. You may refuse the use of advertising cookies at any time by adjusting your preferences via our cookie consent banner or your browser settings.
  • Analytics cookies. Subject to your prior consent, we use Google Analytics on our public marketing pages to understand which pages and campaigns bring visitors to PineHook and how those pages perform. These cookies are never loaded on the authenticated dashboard. You may refuse or withdraw consent at any time via our cookie consent banner or your browser settings.

Analytics and advertising cookies load only after you accept them through our cookie consent banner. Until you do, no such cookie is set and no request is made to any third-party tag. Neither category is ever active on the authenticated dashboard or on account and authentication screens. If your browser sends a Do Not Track or Global Privacy Control signal, we treat it as a refusal and do not load them at all. You may withdraw your consent at any time using the “Cookie preferences” link in our footer or the Data and Privacy section of your dashboard settings.

13. Contact Us

You may contact us to exercise your rights or if you have questions about our practices, procedures, and policies regarding the protection of Personal Information. You may also contact us if you need assistance exercising or understanding your choices regarding the protection of your Personal Information. We will inform individuals who make inquiries or file complaints of the existence of the relevant procedures. PineHook will review all complaints. If a complaint is deemed justified, we will take appropriate action, including, if necessary, modifying our policies and practices. Please feel free to contact us with any questions, inquiries, comments, or complaints regarding your Personal Information.

The person responsible for ensuring compliance with and implementation of this policy, including the handling of rights and complaints, is our Privacy Officer, whose contact information is as follows:

Privacy Officer

PineHook Systems Inc.

204 Saint-Sacrement Street, Suite 300

Montreal, QC H2Y 1W8, Canada

[email protected]

14. Changes to This Privacy Policy

We reserve the right to modify this policy at any time. We therefore encourage you to review it regularly. Changes to this policy will be posted on our Service and on our Website in the form of an updated policy and will take effect upon posting. If we make significant changes to this policy, we will notify you by posting a notice on our Service, our Website, or via email. However, in all other cases, the publication of a new version of the policy on our Service and on our Website or your continued use of the Service or the Website will be sufficient to notify you of the changes made to the policy and to obtain your consent to them.

Appendix 1 — California

This appendix applies solely to the collection and processing of “personal information” as defined by California law. This term refers to any personal information relating to an individual located in California, whether or not that individual is a California citizen. It does not apply if you are outside California, even if you are a U.S. citizen. It is current as of July 7, 2026.

1. What personal information is collected?

Although our processing of personal information varies depending on our relationship and interactions with you, in this section we describe, in general terms, how we have collected and disclosed personal information during the twelve (12) months preceding the last update of this Appendix. For more information, please refer to the sections “Personal information”, “How Do We Collect Personal Information?” and “Why Do We Collect Personal Information?” Below, we identify the categories of personal information (as defined by applicable U.S. laws) that we collect about U.S. residents.

  • Identifiers: include direct identifiers, such as name, username, account number, or unique personal identifier; email address, phone number, address, and other contact information; IP address prior to anonymization and other online identifiers.
  • User Accounts: include personal information, such as name, account name, contact information, account number, and financial or billing information, that individuals provide to us when accessing our Service.
  • Commercial Information: includes records of products or services purchased, obtained, or considered, or other purchase or usage histories or trends.
  • Usage Data: includes browsing history, navigation path data, search history, access logs, and other usage data and information regarding interaction with our Service and Website.
  • Sensitive personal information: includes financial account identifiers.

2. Is your personal information sold?

In accordance with U.S. privacy laws, your Personal Information will never be sold to third parties.

Our Website and Service are not intended for minors, and we do not knowingly collect, let alone sell, any personal information from minors under the age of sixteen (16) through our websites. However, if the parent or guardian of a minor under the age of sixteen (16) believes that the minor has provided us with personal information without the prior and explicit consent of the parent or legal guardian, they should contact us at [email protected] to request the removal of such information from our records.

3. Your Rights

In accordance with U.S. laws, you may have certain rights regarding your personal information, including the rights listed below. To exercise these rights, please contact us at [email protected].

  • Access: You have the right to request, in accordance with applicable laws, that we disclose to you the personal information we have collected, used, shared, and sold (if applicable) about you over the past twelve (12) months. You may request information prior to this period, and we are required to provide it to you, provided that it is feasible to obtain and does not require a disproportionate effort.
  • Deletion: You have the right to request that we delete certain personal information we have collected about you.
  • Opt-out of Sale or Sharing: You have the right to opt out of the sale or sharing of your personal information.
  • Request for Transparency (or Shine the Light): You may also have the right to request that we provide you with (i) a list of certain categories of personal information we have disclosed to third parties for direct marketing purposes during the preceding calendar year and (ii) the identity of those third parties.
  • Correction of Inaccurate Personal Information: You have the right to request that we correct any inaccurate personal information, taking into account the nature of the personal information and the purposes for which the personal information is processed. We will make every reasonable effort to correct inaccurate personal information in accordance with your instructions, subject to applicable U.S. laws.
  • Freedom from Discrimination: You have the right not to be discriminated against in connection with the exercise of your rights.

4. Hosting of Your Personal Information

The personal information of users located in California is hosted on servers in the United States, with backups in Canada.

In connection with the operation and maintenance of the Service, certain personal information may be accessed from Canada by authorized PineHook personnel. This right of access is governed by appropriate contractual, technical, and organizational measures, in accordance with applicable U.S. laws regarding the protection of personal information.

In any event, PineHook undertakes that no sensitive personal information (such as financial account identifiers) will be transferred or hosted outside the territory of the United States and Canada without the implementation of appropriate safeguards in accordance with applicable laws.

5. Anonymous Visits to the Website

Users of the Website may visit our Website anonymously.

Our link to the “Privacy Policy” page includes the word “Privacy” and can be easily found on the page specified above. You will be notified of any changes to this Policy on our Privacy Policy page.

You can modify your personal information:

  • By sending us an email;
  • By calling us.

6. How does our Website handle “Do Not Track” signals?

We honor “Do Not Track” and Global Privacy Control signals. When either is present we do not load analytics or advertising cookies and we do not use advertising, regardless of any preference previously stored on your device.

7. Does our Website allow third-party behavioral tracking?

Only if you consent to it. When you accept advertising cookies, Google may use your browsing activity on our public marketing pages to serve you interest-based advertising. If you decline, or your browser sends a Do Not Track or Global Privacy Control signal, no third-party behavioral tracking takes place. It never takes place on the authenticated dashboard under any circumstances.

8. Fair Information Practices

The principles of fair information practices form the backbone of privacy legislation in the United States, and the concepts they encompass have played a significant role in the development of data protection laws worldwide. Understanding the principles of fair information practices and how they should be implemented is essential to complying with the various privacy laws that protect Personal Information.

To comply with Fair Information Practices, we will take responsive measures. In the event of a breach involving your personal information, we will notify you in written form, including via email or via notification in the Service, as promptly as possible and without unreasonable delay following the breach.

We also accept the principle of individual redress, which requires that individuals have the right to legally enforceable rights against data collectors and processors who do not comply with the law. This principle requires not only that individuals have enforceable rights against data users, but also that they have recourse to courts or government agencies to prosecute and/or investigate non-compliance by data processors.

Appendix 2 — Europe

This appendix applies solely to the collection and processing of “personal data” within the European Union (“EU”). This term refers to any personal information relating to a person located in the EU, whether or not they are a citizen of a member state. This section applies to you if you are located in an EU country. It does not apply if you are outside the EU, even if you are a citizen of a member state.

For the purposes of this appendix, the term “processing” has the meaning given by the General Data Protection Regulation (the “GDPR”) and includes any operation or set of operations performed on EU personal data, such as: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

The EU personal data we process may come directly from you, from a third party (for example, our European partners), or result from your use of our services.

We process this data in accordance with this appendix and our Policy. In the event of any conflict between this appendix and other sections of the Policy regarding the processing of EU personal data, this appendix shall prevail. It is current as of July 7, 2026.

1. Principles of the GDPR

All personal data will be:

  • Processed lawfully, transparently, and fairly;
  • Collected solely for the purposes identified in the Policy or for any other agreed-upon purpose, without further processing incompatible with those purposes;
  • Adequate, relevant, and limited to what is necessary in light of the purposes pursued;
  • Kept up to date in accordance with the “How do we protect your information?” section of the Policy;
  • Retained in a form that permits identification only for as long as is necessary for the intended purposes;
  • Stored and processed securely to prevent unauthorized access, loss, damage, or accidental disclosure, in accordance with the Policy.

2. Legal Bases for Processing

We collect and process personal data only if we have a legal basis to do so, including:

  • Your consent;
  • The necessity of processing to fulfill a contract with you (for example, providing the requested services);
  • The necessity of processing for the “legitimate interests” of PineHook, provided that these interests do not override your rights and freedoms. Certain legitimate interests are specified in the “Why do we collect Personal Information?” section of the Policy.

When we rely on your consent, you may withdraw, restrict, or refuse it at any time. When we rely on a legitimate interest, you may object to it. For any questions regarding legal bases, please refer to the “What are your rights?” section of the Policy.

We do not use automated decision-making, including profiling, for decisions that produce legal effects on you.

3. Rights of Data Subjects

In addition to the rights set forth in the Policy, you have the following rights regarding your personal data:

  • Access and portability: You may request a copy of your data (as well as any information provided for under Article 15 of the GDPR) and receive this data in a structured, commonly used, and machine-readable format, including for the purpose of transferring it to a third party.
  • Restriction and objection: You may request the restriction or cessation of the processing of your data, particularly if you believe that such processing is unlawful or if it is used for direct marketing purposes.

4. Responsibilities as a Data Controller

In general, we act as the “data controller” for personal data. In this capacity, we:

  • Explain, in this Policy, how we collect, store, disclose, and process this data;
  • Only appoint processors under agreements compliant with the GDPR;
  • Maintain a record of processing activities when required;
  • Cooperate with the competent authorities;
  • Implement appropriate technical and organizational measures to protect the data and report any breaches in accordance with the “How do we protect your information?” section of the Policy.

5. Disclosure to Third Parties

If we need to disclose your data to third parties (including processors), we require them to comply with the GDPR. In the event of a transfer outside the EU, this will be carried out within the scope of the lawful performance of our services.

6. Hosting of Personal Data

The personal data of users located in the EU is hosted on servers located in the United States, with backups in Canada. As part of the operation and maintenance of the Service, certain personal data may be accessed remotely from Canada by authorized PineHook personnel. These rights regarding data storage and access are governed by appropriate contractual, technical, and organizational measures and are based, in particular, on the adequacy decision issued by the European Commission regarding Canada and the EU-US Data Privacy Framework, recognizing a sufficient level of protection within the meaning of the GDPR.

7. Consent to Transfer

By accepting this Policy, you consent to the transfer of your personal data to third parties located outside the EU. You acknowledge that we are not responsible for such third parties’ compliance with their obligations under the GDPR.

For any comments, questions, or complaints regarding the processing of your personal data, or to exercise your rights, please use the contact information provided in the “Contact Us” section of the Policy. Your requests will be handled in accordance with the “What are your rights?” section.

Appendix 3 — United Kingdom

This appendix applies only to the collection and processing of “personal data” in the United Kingdom (“UK”). This term refers to any personal information relating to an individual located in the UK, whether or not they are a UK citizen. This section applies to you if you are located in the UK. It does not apply if you are outside the UK, even if you are a UK citizen.

For the purposes of this appendix, the term “processing” has the meaning given by the UK General Data Protection Regulation (the “UK GDPR”) and the UK Data Protection Act 2018 (the “DPA 2018”), and includes any operation or set of operations performed on UK personal data, such as: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

The UK personal data we process may come directly from you, from a third party (for example, our European partners), or result from your use of our services.

We process this data in accordance with this appendix and our Policy. In the event of any conflict between this appendix and other sections of the Policy regarding the processing of UK personal data, this appendix shall prevail. It is current as of July 7, 2026.

1. GDPR Principles

All personal data will be:

  • Processed lawfully, transparently, and fairly;
  • Collected only for the purposes identified in the Policy or for any other agreed-upon purpose, without further processing incompatible with those purposes;
  • Adequate, relevant, and limited to what is necessary in relation to the purposes pursued;
  • Kept up to date in accordance with the “How do we protect your information?” section of the Policy;
  • Retained in a form that permits identification only for as long as is necessary for the intended purposes;
  • Stored and processed securely to prevent unauthorized access, loss, damage, or accidental disclosure, in accordance with the Policy.

2. Legal Bases for Processing

We collect and process personal data only if we have a legal basis to do so, including:

  • Your consent;
  • The necessity of processing to fulfill a contract with you (for example, providing the requested services);
  • The necessity of processing for the “legitimate interests” of PineHook, provided that these interests do not override your rights and freedoms. Certain legitimate interests are specified in the “Why do we collect Personal Information?” section of the Policy.

When we rely on your consent, you may withdraw, restrict, or refuse it at any time. When we rely on a legitimate interest, you may object to it. For any questions regarding legal bases, please refer to the “What are your rights?” section of the Policy.

We do not use automated decision-making, including profiling, for decisions that produce legal effects on you.

3. Rights of Data Subjects

In addition to the rights set forth in the Policy, you have the following rights regarding your personal data:

  • Access and portability: You may request a copy of your data (as well as any information provided for under Article 15 of the UK GDPR) and receive this data in a structured, commonly used, and machine-readable format, including for the purpose of transferring it to a third party.
  • Restriction and objection: You may request the restriction or cessation of the processing of your data, particularly if you believe that such processing is unlawful or if it is used for direct marketing purposes.

4. Responsibilities as a Data Controller

In general, we act as the “data controller” for personal data. In this capacity, we:

  • Explain, in this Policy, how we collect, store, disclose, and process this data;
  • Only appoint processors under agreements compliant with the UK GDPR;
  • Maintain a record of processing activities when required;
  • Cooperate with the competent authorities;
  • We implement appropriate technical and organizational measures to protect data and report any breaches in accordance with the “How do we protect your information?” section of the Policy.

5. Disclosure to Third Parties

If we need to disclose your data to third parties (including processors), we require them to comply with the UK GDPR and the DPA 2018. In the event of a transfer outside the UK, it will be carried out in connection with the lawful performance of our services.

6. Hosting of Personal Data

The personal data of users located in the UK is hosted on servers located in the United States, with backups in Canada. As part of the operation and maintenance of the Service, certain personal data may be accessed remotely from Canada by authorized PineHook personnel. These rights regarding data storage and access are governed by appropriate contractual, technical, and organizational measures and are based, in particular, on the adequacy decision issued by the UK Secretary of State regarding Canada and the United States, recognizing a sufficient level of protection within the meaning of the UK GDPR.

7. Consent to Transfer

By accepting this Policy, you consent to the transfer of your personal data to third parties located outside the UK. You acknowledge that we are not responsible for such third parties’ compliance with their obligations under the UK GDPR.

For any comments, questions, or complaints regarding the processing of your personal data, or to exercise your rights, please use the contact details provided in the “Contact Us” section of the Policy. Your requests will be handled in accordance with the “What are your rights?” section.